Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At which point, how do you identify which is a user-specific issue vs a site or fractional-site wide one?

And who's responsible for building that list? Does the vendor have to add things manually? Is there a submission process? How do you stop genuine malware sites from hosting multiple copies on subdomains and claiming innocence?

What about where you don't use subdomains, but a url structure like example.com/user/file/?

Making exceptions always sounds like the easy option, until you have to try doing it, and running it at any scale.



>At which point, how do you identify which is a user-specific issue vs a site or fractional-site wide one?

Separate subdomains, having a human spend 30 seconds clicking around and deciding "Oh, this is a file locker. Obviously not a malware host or infected site. Whitelisted".

>And who's responsible for building that list? Does the vendor have to add things manually? Is there a submission process?

The vendor. Which is how its done already. So yes and depends.

>How do you stop genuine malware sites from hosting multiple copies on subdomains and claiming innocence?

This is Dropbox, not TotallyLegitFiles302.ru

I see what you're getting at, but something this high visiblity (and obviousness to pretty much everyone) points to something rotten in their process somewhere.

Furthermore, it's more effective and efficent to just register a new domain than to haggle (in broken english, another red flag) with the platform owner.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: